checking-session-security

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Checking Session Security

检查会话安全

Overview

概述

This skill provides automated assistance for the described functionality.
本Skill为上述功能提供自动化辅助。

Prerequisites

前提条件

Before using this skill, ensure:
  • Source code accessible in {baseDir}/
  • Session management code locations known (auth modules, middleware)
  • Framework information (Express, Django, Spring, etc.)
  • Configuration files for session settings
  • Write permissions for security report in {baseDir}/security-reports/
使用本Skill前,请确保:
  • 源代码可在{baseDir}/目录下访问
  • 已知会话管理代码的位置(认证模块、中间件)
  • 框架信息(Express、Django、Spring等)
  • 会话设置的配置文件
  • 拥有在{baseDir}/security-reports/目录下写入安全报告的权限

Instructions

操作步骤

  1. Review session creation, storage, and transport security controls.
  2. Validate cookie flags, rotation, expiration, and invalidation behavior.
  3. Identify common attack paths (fixation, CSRF, replay) and mitigations.
  4. Provide prioritized fixes with configuration/code examples.
See
{baseDir}/references/implementation.md
for detailed implementation guide.
  1. 审查会话创建、存储和传输的安全控制措施。
  2. 验证Cookie标记、轮换、过期和失效行为。
  3. 识别常见攻击路径(固定攻击、CSRF、重放攻击)及缓解措施。
  4. 提供带有配置/代码示例的优先级修复方案。
请查看
{baseDir}/references/implementation.md
获取详细的实现指南。

Output

输出

The skill produces:
Primary Output: Session security report saved to {baseDir}/security-reports/session-security-YYYYMMDD.md
Report Structure:
undefined
本Skill生成以下内容:
主要输出:会话安全报告保存至{baseDir}/security-reports/session-security-YYYYMMDD.md
报告结构
undefined

Session Security Analysis Report

Session Security Analysis Report

Analysis Date: 2024-01-15 Application: Web Portal Framework: Express.js
Analysis Date: 2024-01-15 Application: Web Portal Framework: Express.js

Error Handling

Error Handling

See
{baseDir}/references/errors.md
for comprehensive error handling.
See
{baseDir}/references/errors.md
for comprehensive error handling.

Examples

Examples

See
{baseDir}/references/examples.md
for detailed examples.
See
{baseDir}/references/examples.md
for detailed examples.

Resources

Resources